4 ms·
> Operating systems are in a sad state, as virtual address spaces already offer exactly that in hardware at full speed Ever since reading about Microsoft Singu
by james412 6y ago
> Operating systems are in a sad state, as virtual address spaces already offer exactly that in hardware at full speed
Ever since reading about Microsoft Singularity all that time ago, I reached the opposite conclusion: software is in such a sad state that it must rely on hardware to provide isolation. From this perspective, WasmBoxC and many projects like it are IMO a huge step in a desirable direction.
The main lesson from Singularity for me (aside from requirements for memory safety) was that cross-component safety can be achieved by formalizing the protocols those components use to communicate. Sing# had a dedicated type to capture the state machine for every cross-component transaction, with strongly typed inputs and outputs. This problem is not unique to software isolation -- it is the basis for a huge variety of security problems everywhere across the ecosystem, not least network services
Wouldn't it be a wonderful world if we knew our application was fully safe when exposed to a network for the same reason we know it is fully safe to run in the same address space as another untrusted application? That is that path Singularity took us along
- pjmlp 6y agoExample of such sad state of affairs, Android 11 is adding support for hardware memory tagging, as static analysis alone is not enough to tame the C and C++ components. https://source.android.com/devices/tech/debug/tagged-pointers https://source.android.com/devices/tech/debug/tagged-pointer... iOS, Solaris on SPARC are on this path as well. Regarding Singularity, we are slowly moving away from C on non pure UNIX clones, but still it will take generations.